For software vendors
This page explains how organisations ensure the development of their software (or software services) aligns with the Code, (which is available from the DSIT website).

How vendors can comply with the Software Security Code of Practice
- 1
Understand the Code of Practice
- Read the Code of Practice to understand its purpose, principles, and requirements
- Review the Implementation Guidance to understand how to meet the Code’s expectations.
- Read the Code of Practice to understand its purpose, principles, and requirements
- 2
Assess requirements and plan implementation
- Use the Assurance Principles and Claims (APC) document to assess your own software practices against the Code of Practice
- Record your assessment using the APC Self-assessment.
- Develop a plan to implement solutions to evidence the claims.
- Use the Assurance Principles and Claims (APC) document to assess your own software practices against the Code of Practice
- 3
Implement your solutions
- Use your initial assessment to prioritise solutions.
- Use the APC Self-assessment to track and document progress.
- Use your initial assessment to prioritise solutions.
- 4
Continuous improvement
- Conduct regular audits using the APC Self-assessment to monitor compliance.
- Update security practices based on changes in the Code and emerging threats.
- Conduct regular audits using the APC Self-assessment to monitor compliance.
We invite you to contribute to the Monitoring and Evaluation of the Software Security Code of Practice to assess the effectiveness of this policy and guide future policy decisions. Share your views as a software vendor.